CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlinklog: initialize nfgenmsg in NLMSGDONE terminator
When batching multiple NFLOG messages (inst->qlen > 1), nfulnlsend() appends an NLMSGDONE terminator with sizeof(struct nfgenmsg) payload via nlmsgput(), but never initializes the nfgenmsg bytes. The nlmsgput() helper only zeroes alignment padding after the payload, not the payload itself, so four bytes of stale kernel heap data are leaked to userspace in the NLMSGDONE message body.
Use nfnlmsgput() to build the NLMSGDONE terminator, which initializes the nfgenmsg payload via nfnlfillhdr(), consistent with how buildpacketmessage() already constructs NFULNLMSGPACKET headers.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to Linux kernel systems using NFLOG and batching multiple NFLOG messages, where the queue length is greater than one. The CVSS vector indicates local access and low privileges are required.
What must occur for kernel data to be disclosed?
The vulnerable path is reached when __nfulnl_send() builds an NLMSG_DONE terminator for a batch of multiple NFLOG messages. The uninitialized nfgenmsg payload in that terminator can disclose four bytes of stale kernel heap data to userspace.
How can the vulnerable implementation be distinguished from the corrected one?
The vulnerable implementation creates the NLMSG_DONE terminator with nlmsg_put() without initializing the nfgenmsg payload. The corrected implementation uses nfnl_msg_put(), which initializes that payload through nfnl_fill_hdr().